Skip to content

Denmark’s CPR data breach exposes 8.8 million records

Denmark’s Central Person Register (CPR) has suffered a major data breach, with unauthorized access to approximately 8.8 million records containing names, addresses, and ID numbers. The breach was detected after an unusually large invoice for lookups, prompting a government investigation. Authorities are reviewing security measures but have not yet identified suspects or committed to issuing new ID numbers.

Editor, Lazyfounder

Published 5 min read
Denmark’s CPR data breach exposes 8.8 million records
Image: Nyhavn in Copenhagen, Denmark via source

Denmark’s Central Person Register (CPR) has suffered a major data breach, with unauthorized access to approximately 8.8 million records containing names, addresses, and ID numbers. The breach was detected after an unusually large invoice for lookups, prompting a government investigation. Authorities are reviewing security measures but have not yet identified suspects or committed to issuing new ID numbers.

30 SEC SUMMARY

  • Denmark’s Central Person Register (CPR) experienced a data breach affecting approximately 8.8 million records, including names, addresses, and ID numbers.
  • The breach was discovered after an unusually large invoice for unauthorized lookups, totaling over 14 million attempts over ten days in September.
  • No individuals have been identified or charged, and the ministry has not named the company involved in the breach.
  • Authorities are conducting a security review of the CPR system but have not yet decided on issuing new ID numbers.
  • Officials advised against using CPR numbers alone as proof of identity and warned of potential phishing risks.

TABLE OF CONTENTS

  • Breach discovery and scope
  • Response and investigation
  • Security recommendations
  • Broader implications
  • What this means
  • Key takeaways
  • FAQ
  • Sources

KEY HIGHLIGHTS

  • Approximately 8.8 million records were accessed in Denmark’s CPR breach, including names, addresses, and ID numbers.
  • The breach involved over 14 million unauthorized lookup attempts over ten days in September.
  • Authorities discovered the breach after noticing an unusually large invoice for the lookups.
  • No individuals have been charged, and the company responsible remains unnamed.
  • Officials warned against using CPR numbers alone as proof of identity and advised vigilance against phishing.

Breach discovery and scope

Denmark’s Central Person Register (CPR) experienced a significant data breach involving unauthorized access to approximately 8.8 million records, according to The Next Web. The compromised data includes names, addresses, and ID numbers.

The breach was discovered on the evening of 2 October after the CPR administration flagged an unusually large invoice for lookups. Investigations revealed that over 14 million lookup attempts had been made over ten days in September, with 8.8 million returning valid records.

The CPR register holds about 11 million records, encompassing current residents, deceased individuals, and those who have emigrated. Denmark has a population of approximately 6 million residents.

Response and investigation

Danish authorities, including officers from the National Unit for Special Crime, visited the unidentified company involved in the breach to secure evidence. However, no individuals have been identified or charged in connection with the incident.

Christina Egelund, Denmark’s Minister for Science, Higher Education and Digital Affairs, has ordered a security review of the CPR system. It remains unclear whether affected individuals will receive new CPR numbers.

The ministry has not disclosed the name of the company responsible for the unauthorized lookups. According to The Next Web, private companies with a legitimate interest can access CPR data under section 38 of the Danish Civil Registration System Act.

Security recommendations

Authorities confirmed that the breach did not affect individuals who had opted for name and address protection. Additionally, systems using MitID, Denmark’s national digital login, were not compromised.

Egelund advised companies and public authorities to stop accepting a CPR number alone as proof of identity. She also warned Danes to be cautious of phishing attempts, as criminals could exploit the stolen data for fraudulent activities.

Mikkel Leihardt, Department Head at the Danish Ministry of Digitalisation, stated that the CPR identification system is "broken." The ministry is assessing potential improvements but has not announced specific measures.

Broader implications

The breach has raised concerns about the security of national identity systems and the potential for identity theft. Styrelsen for Samfundssikkerhed, Denmark’s Agency for Civil Security, is collaborating with other agencies to mitigate risks.

Digital investigator Jan Kaastrup and Laila Reenberg, Director of Styrelsen for Samfundssikkerhed, emphasized the need for heightened vigilance among individuals and organizations handling sensitive data.

What this means

Lazyfounder analysis — our interpretation, not reported fact.

This breach underscores the vulnerabilities in national identity systems, even in countries with advanced digital infrastructure. For founders and operators, it’s a stark reminder that relying on a single identifier—like Denmark’s CPR number—for authentication or verification is risky. The incident also highlights the importance of monitoring unusual activity in real time, especially for systems handling sensitive data. While Denmark’s response, including a security review and public warnings, is a necessary first step, the lack of immediate consequences for the perpetrators may signal a longer-term challenge for trust in digital identity systems. Companies and governments alike should reconsider how they use and protect foundational identifiers.

Key takeaways

  • Denmark’s CPR breach exposed 8.8 million records, highlighting gaps in security for national identity systems.
  • Unauthorized access went undetected for ten days, raising questions about monitoring and alert systems.
  • The breach did not affect MitID, Denmark’s national digital login, but officials warned against relying solely on CPR numbers for identity verification.
  • No suspects have been identified, and the company involved remains unnamed, delaying accountability.
  • Authorities are reviewing CPR security but have not committed to issuing new ID numbers for affected individuals.

FAQ

What is the Central Person Register (CPR)?

The CPR is Denmark’s national registry, containing identification details such as names, addresses, and ID numbers for residents, deceased individuals, and emigrants. It is used for administrative and verification purposes.

How was the breach discovered?

The breach came to light when the CPR administration noticed an unusually large invoice for lookups, which led to an investigation revealing over 14 million unauthorized attempts.

Has anyone been charged in connection with the breach?

No. As of now, no individuals have been identified or charged in relation to the breach.

Will affected individuals receive new CPR numbers?

It is too early to say. The Danish Ministry for Science, Higher Education and Digital Affairs has not decided whether to issue new CPR numbers for those affected.

What should individuals and companies do in response to the breach?

Authorities have advised against using CPR numbers alone as proof of identity and urged heightened caution against phishing attempts. Companies should review their security protocols for handling sensitive data.

Related on Lazyfounder

Sources

  1. The Next Web · 2026-10-06
    Denmark’s CPR breach: 14 million lookups in ten days, found through a bill

This story is an original summary drafted with AI by Lazyfounder from the reporting listed above and checked by automated validation. Facts are attributed to their original publishers; sections marked as analysis are Lazyfounder's. Where a source is in another language, facts were machine-translated and quotations are reported, not reproduced. Read the original coverage via the links, and see our AI policy and corrections policy.

About the author

Editor, Lazyfounder

Tarun Mottlia edits LazyFounders, covering Indian startups, funding rounds, AI and product launches. Every story on the site is AI-assisted and checked against its cited sources before publication.

More stories by Tarun Mottlia

Get the LazyFounder Brief

Startup, funding and AI news in a five-minute read. Join the early-access list.

Lazy Founder - Powered by Blogy.in

Contact us

Have a story tip, correction or partnership idea?

Write to us at tarun.kumar@blogy.in or talk to the founder directly. We read every message.

Contact us